Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
08/09/2026
[CVE-2026-68846] Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-68835] Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileg…
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-68837] Use after free in Windows File History Service allows an authorized attacker to elevate privileges l…
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-68840] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-68824] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-68825] Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges loc…
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-67385] Use after free in SQL Server allows an authorized attacker to execute code over a network.
Use after free in SQL Server allows an authorized attacker to execute code over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-62813] Use after free in Active Directory Domain Services allows an authorized attacker to execute code ove…
Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-62694] Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-62697] Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges loc…
Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-56172] Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges lo…
Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-56177] Use after free in Windows Server allows an authorized attacker to elevate privileges locally.
Use after free in Windows Server allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-50349] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-82061] A use-after-free security issue exists in the server's query execution memory tracking subsystem. An…
A use-after-free security issue exists in the server's query execution memory tracking subsystem. An authenticated user with read privileges can trigger a write to freed heap memory through a sequence of standard database commands, leading to server process crash or potential memory corruption. No user interaction is required.
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en PX4 Autopilot 1.17.0 y anteriores: use-after-free en módulo load_mon
PX4 Autopilot versiones hasta 1.17.0 contiene una vulnerabilidad use-after-free en el módulo load_mon que permite a atacantes ejecutar comandos maliciosos a través de shells PXH o MAVLink, causando corrupción de memoria. Esta falla afecta directamente sistemas de vehículos autónomos, drones industriales y equipos de defensa en operaciones altas en LATAM, siendo explotable sin autenticación en entornos accesibles.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85197] A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can ex…
A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in informat…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85048] Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who …
Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85049] Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute …
Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85042] Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to exec…
Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
03/09/2026
[CVE-2026-33630] c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-…
c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the channel's internal lookup structures — is present at multiple points in the resend/finish path (timeout handling, response handling, and query dispatch). If the query, o…